Method of Providing Digital Certificate Functionality
Abstract
There is described a method of providing certification functionality. The method involves: (a) at a certification authority ( 20 ), generating a secret P, applying the secret P to sign a data string (m A ) on behalf of a first device ( 30, A), and communicating ( 50 ) the signed string to the first device ( 30, A); (b) communicating ( 60 ) secret information from the authority ( 20 ) to a second device (B, 40 ), the secret information for verifying authenticity of the string (m A ), the second device ( 40, B) being operable to use the secret information to generate a second key (k AB2 ); (c) generating a first key (k AB1 ) at the first device ( 30, A) using public information pertaining to the second device ( 40, B), said first key (k AB I) being susceptible to generation provided that the string is authentic; (d) applying the second key (k AB2 )to protect data for communication from the second device ( 40, B) to the first device ( 30, A); and (e) at the first device ( 30, A), applying the first key (k AB1 )to access the protected data communicated from the second device ( 40, B) to the first device ( 30, A).
Claims
exact text as granted — not AI-modified1 . A method of providing digital certification functionality in a network ( 10 ) comprising a certification authority ( 20 ) and at least first and second devices ( 30 , 40 ) connectable in communication with the authority ( 20 ), the method including steps of:
(a) at the authority ( 20 ), generating a secret P, applying the secret P to sign a data string (m A ) on behalf of the first device ( 30 , A), and then communicating ( 50 ) the signed string to the first device ( 30 , A); (b) communicating ( 60 ) secret information from the authority ( 20 ) to the second device (B, 40 ), said secret information for verifying authenticity of the string (m A ), said second device ( 40 , B) being operable to use the secret information to generate a second key (k AB2 ) for verifying authenticity of the string (m A ); (c) generating a first key (k AB1 ) at the first device ( 30 , A) using public information pertaining to the second device ( 40 , B), said first key (k AB1 ) being susceptible to generation provided that the string (m A ) is authentic; (d) applying the second key (k AB2 ) to protect data for communication from the second device ( 40 , B) to the first device ( 30 , A); and (e) at the first device ( 30 , A), applying the first key (k AB1 ) to access the protected data communicated from the second device ( 40 , B) to the first device ( 30 , A).
2 . A method according to claim 1 , wherein accessing the protected data in step (e) is implemented without requiring on-line access to the authority ( 20 ) during verification.
3 . A method according to claim 1 , wherein the secret P is a bi-variate polynomial.
4 . A method according to claim 1 , wherein the first key (k AB1 ) is a polynomial evaluated using a public string relating to the second device ( 40 , B).
5 . A method according to claim 1 , wherein, in step (a), the signed string is communicated secretly from the authority ( 20 ) to the first device ( 30 , A).
6 . A method according to claim 5 , wherein the signed string is communicated secretly using encryption techniques,
7 . A method according to claim 1 , wherein verification of the communicated protected data at the first device ( 30 , A) is explicit.
8 . A method according to claim 1 , wherein verification of the communicated protected data at the first device ( 30 , A) is implicit.
9 . A method according to claim 1 based on at least one of: Blom's scheme, Identity Based Encryption (IBE).
10 . A communication system ( 10 ) including a certification authority (CA, 20 ) and a plurality of devices ( 30 , 40 ) arranged in mutual communication, the system ( 10 ) being operable according to the method of claim 1 .
11 . A digital certificate for data verification in a communication network ( 10 ) operable according to a method of claim 1 .
12 . Encrypted data susceptible to verification by applying a method according to claim 1 .
13 . Encrypted data according to claim 12 , said data including audio and/or video program content.Join the waitlist — get patent alerts
Track US2008098213A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.